Coturn是Coturn组织开源的一款实现TURN协议的服务器软件。 Coturn 4.15.0至4.16.0之前版本存在资源管理错误漏洞,该漏洞源于移动性会话恢复处理不当,导致会话分配超时被解除和链接覆盖,且配额检查失败被忽略,可能导致经过身份验证的攻击者保留无限制的服务器端会话并耗尽进程内存。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-68553 | 7.1 HIGH | Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command |
| CVE-2026-68552 | 5.3 MEDIUM | Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypa |
| CVE-2026-68554 | 2.3 LOW | Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers m |
No comments yet